Kyser, Nancy 


Attachments: 


From: 

Sent: 

To: 

Cc: 

Subject: 


Schmidt, Kari 

Friday, June 21, 2019 12:21 PM 
Kyser, Nancy 

Mutter, Nicole; Forch, Jessica 

FW: Nebraska Public Records Act Request: Criminal Hackers Target Police to Protest 
Perceived Injustices (Nebraska State Patrol) 

DHS-FBI-HackersTargetPolice.pdf 


Kari Schmidt 

Paralegal 1 

Nebraska State Patrol 

1600 NE Highway 2 
Lincoln, Nebraska 68502 
OFFICE 402-479-4910 
kari.schmidt@nebraska.qov 

statepatrol.nebraska.qov 

* CONFIDENTIALITY NOTICE: This message (including any attacliments) may contain confidential 
information, protected by law. If this message is confidential, forwarding, disclosure, copying, or distribution of 
this message or taking of any action based upon it, is strictly prohibited. If you have received this email in 
error, please delete it immediately and contact the sender.** 


From: 75716-27063081(S)requests.muckrock.com <75716-27063081(a)requests.muckrock.com> 

Sent: Friday, June 21, 2019 12:13 PM 

To: Schmidt, Kari <Kari.Schmidt(5)nebraska.gov> 

Subject: Nebraska Public Records Act Request: Criminal Hackers Target Police to Protest Perceived Injustices (Nebraska 
State Patrol) 


Nebraska State Patrol 
Nebraska Public Records Act Office 
P.O. Box 94907 
Lincoln, NE 68509 

June 21, 2019 

To Whom It May Concern: 

Pursuant to the Nebraska Public Records Act, I hereby request the following records: 

Records mentioning, describing or generated as a result of the 8 May 2015 Roll Call Release IA-0181-15 
(which was designed to be shared widely with law enforcement) from the Department of Homeland Security's 
Office of intelligence and Analysis (I&A) in conjunction with the Federal Bureau of Investigation, titled 


1 





"Criminal Hackers Target Police to Protest Perceived Injustices," as well as records otherwise responding or 
reacting to the issues raised in it. 

I am a member of the news media and request classification as such. I have previously written about the 
govermiient and its activities, with some reaching over 100,000 readers in outlets such as Gizmodo, MuckRock, 
Motherboard, Property of the People, Unicorn Riot, and The Outline, among others. As such, as I have a 
reasonable expectation of publication and my editorial and writing skills are well established. In addition, I 
discuss and comment on the files online and make them available tlnough non-profits such as the library 
Internet Archive and the journalist non-profit MuckRock, disseminating them to a large audience. While my 
research is not limited to this, a great deal of it, including this, focuses on the activities and attitudes of the 
government itself 

As my primary purpose is to inform about government activities by reporting on it and making the raw data 
available, I request that fees be waived. 

The requested documents will be made available to the general public, and this request is not being made for 
commercial purposes. 

In the event that there are fees, I would be grateful if you would inform me of the total charges in advance of 
fulfilling my request. I would prefer the request filled electronically, by e-mail attacliment if available or CD- 
ROM if not. 

Thank you in advance for your anticipated cooperation in this matter. I look forward to receiving your response 
to this request within 4 business days, as the statute requires. 

Sincerely, 

Emma Best 

Filed via MuckRock.com 

E-mail (Prefened): 75716-2706308l@requests.mucki’ock.com 
Upload documents directly: 

https://accounts.muckrock.com/accounts/login/?url_auth_token=AAAWGGv2sSTdNFHZsLSXtlzlIwY%3Alh 

eN5m%3AOYY9vobk9SCtTMOpvi8ArHNqVik&nextMittps%3A%2F%2Fwww.muckiock.coni%2Faccounts 

%2Flogin%2F%3Fnext%3D%252Faccounts%252Fagency__login%252Fnebraska-state-patrol- 

838%252Fcriminal-hackers-target-police-to-protest-perceived-injustices-nebraska-state-patrol- 

75716%252F%253Femail%253Dkari.schinidt%252540nebraska.gov 

Is this email coming to the wrong contact? Something else wrong? Use the above link to let us know. 

For mailed responses, please address (see note): 

MuckRock News 
DEPT MR 75716 
411A Highland Ave 
Somerville, MA 02144-2516 

PLEASE NOTE: This request is not filed by a MuckRock staff member, but is being sent tlnough MuckRock 
by the above in order to better track, share, and manage public records requests. Also note that improperly 
addressed (i.e., with the requester’s name rather than "MuckRock News" and the department number) requests 
might be returned as undeliverable. 
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UNCLASSIFIED//FOR OFFICIAL USE ONLY 






ROLL CALL RELEASE 

INTELLIGENCE FOR POLICE. FIRE. EMS. AND SECURITY PERSONNEL 




f - 
•» 


8 May 2015 


(U//FOUO) Cnminal Hackers Target Police to Protest Perceived Injustices 

(U//FOUO) Disruptive cyber attacks by criminal hackers—primarily 
distributed-denial-of-service (DDoS) attacks—targeting local law enforcement 
websites have increased since August 2014. We judge that this is almost 
certainly a result of the heightened coverage surrounding the alleged use of 
excessive force by law enforcement and an increased focus on incidents of 
perceived police brutality. The primary impact from the majority of these 
attacks has been the temporary disruption of the targeted public-facing websites. 

» (U//FOUO) In 2014, the Multi-State Information Sharing and Analysis 
Center (MS-ISAC) observed 53 separate incidents of criminal hackers 
conducting cyber operations against state and local entities in response to 
incidents of alleged use of excessive force by law enforcement. The majority of these incidents were low to 
moderate in effect, most frequently resulting in temporary disruption to targeted websites. 

» (U//FOUO) On the morning of 30 December 2014, unknown criminal hackers disabled a Midwestern police 
department’s public website using a DDoS attack. A post later that morning on a US social-networking site 
containing the hashtag “#BlackLives Matter” announced that the targeted website was down. The disabling 
of this website was the third successful attack to disable a law enforcement website in the state within a week— 
the attacks were limited to the temporary disablement of targeted websites, according to DHS field reporting. 

» (U//FOUO) A criminal hacker using the moniker (at)DigitaShadow claimed responsibility on a US social-media site 
for disrupting access to a Northwestern city police department’s website in early December 2014. The DDoS 
attack, which lasted approximately 10 minutes, prevented the department’s in-car terminals from transmitting or 
receiving traffic, including 91 I dispatch requests, according to FBI reporting. 

(U//FOUO) MS-ISAC Distributed-Denial-of-Service Mitigation Recommendations 
(U) Proactive protections include: 

» (U) Establish connections v/ith multiple Internet service providers (ISPs) for redundancy, 

» (U) Ensure service-level agreements with ISPs contain provisions for DoS prevention (such as IP address rotation), 

» (U) Conduct rate-limiting of traffic at the nework perimeter, and 

» (U) Create backup, remote-site network infrastructure using multiple addressing schemes. 

(U) Reactive protections include: 

» (U) Execute ISP address rotation, 

» (U) Block source IP addresses generating DoS traffic at enterprise boundary or within ISP infrastructure, and 

» (U) Acquire increased bandwidth capability from the ISP. 

(U//FOUO) See MS-ISAC’s “Guide to DDoS Attacks” for additional information: 
http://msisac.cisecurity.org/resources/reports/ documents/GuldetoDDoSAttacks__OOO.pdf. 



(U) Reporting Computer Security Incidents 


(U) To report a computer security incident, either contact US-CERT at 888-282-0870, or go to https://forms.us-cert.gov/report/ and 
complete the US-CERT Incident Reporting System form. The US-CERT Incident Reporting System provides a secure, web-enabled means of 
reporting computer security incidents to US-CERT. An incident is defined as a violation or imminent threat of violation of computer security policies, 
acceptable use policies, or standard computer security practices. In general, types of activity commonly recognized as violating typical security policies 
include attempts (either failed or successful) to gain unauthorized access to a system or its data, Including personally identifiable Information; unwanted 
disruption or denial of service; the unauthorized use of a system for processing or storing data; and changes to system hardware, firmware, or software 
without the owner’s knowledge, instruction, or consent 


IA-0I8I-I5 


(U) Prepared by the Office ofintelSgence andAna}fSK (l&A). Coordnaled wtb the FBL This product Is intended to provide cybersecurity awareness to federal stat^ local ond private sector first responders in matters that 
can affect personnel and network security of their respective organizations. 

(U) Warning: This document is UNCLASSIPIED//FOR OFFICIAL USE ONLY (U/IFOUO). It contains infornxjtion that may be exempt from pubic release under the Freedom of Information Act (5 U.S.C 552). It is to be 
controBed, store4 handled transmitted, dslhbuted and dsposed of in accordance with DHS poky relating to FOUO information and is no! lo be released to the pubk, the media, or other personnel n-ho do not have a voSd 
need to know Mthout prior approval of an authorized DHS offidal State and heal honreland security officials may share this document uith authorized critical infrastructure and key resource personnel and private sector 
security officials without further approval from DHS. 
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